Overview:
Overview:
This page is a resource on how to configure Thoropass SSO login, using Microsoft Azure Entra App Gallery.
What is Microsoft Entra App Gallery?
Microsoft Entra App Gallery is an app store where the Thoropass "SSO Installer Application" can be downloaded.
Downloading Thoropass from the Azure Entra App Gallery, will save considerable time and errors in configuring SSO login with Thoropass.
What is the overall process to configure Thoropass SSO login?
The following diagram illustrates the Thoropass SSO configuration process, which is outlined in more detail below.
Part 1: SSO Metadata URL
Part 1: SSO Metadata URL
Navigate to Thoropass -> Settings -> Authentication and click "SET UP SAML"
Choose Azure from the list and click Continue
In Azure, install Thoropass here in the Azure Entra App Gallery
In Azure, copy the "App Federation Metadata URL" provided
Azure automatically provides a "Metadata URL" once Thoropass is installed.In Thoropass, paste the Metadata URL and click Continue
(Optional) To add Thoropass to your SSO Provider Dashboard screen, copy the Relay State URL in Thoropass and add it to the Azure -> Sign On -> Relay State Field.
Part 3: Test SSO Login & Enable Thoropass SSO
Part 3: Test SSO Login & Enable Thoropass SSO
Use the "TEST URL" to confirm the SSO config works before enabling SSO:
Copy the "TEST URL"
Open the URL in an Incognito browser window and attempt SSO login
The TEST URL will automatically redirect to your SSO login
If SSO login is successful, you will navigate to the Thoropass application
Click the "Confirm" checkbox IF the Test URL login was successful
Click “Configure” to enable Thoropass SSO login for your organization
Once enabled, the Thoropass login page (login.thoropass.com) will redirect all users with the email domains you provided, to your SSO login. Only provisioned users for Thoropass, in your SSO provider, can log in.
FAQs
How to disable SSO login and Re-Enable Standard Login?
Navigate to Thoropass -> Settings -> Authentication
Select "Disable" in the SAML SSO Login and follow the prompts
Standard login will be automatically enabled
Navigate to Settings -> Users and "Reinvite" ALL users in the list
Important Note: Once SSO is Disabled, No users will be able to login again until they are "reinvited", including the Admin who is disabling SSO.